Lucene search

K
cve[email protected]CVE-2014-0337
HistoryApr 05, 2014 - 4:01 a.m.

CVE-2014-0337

2014-04-0504:01:37
CWE-79
web.nvd.nist.gov
28
cve-2014-0337
cross-site scripting
xss
huawei
echo life
hg8247
router security
vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.1%

Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted username that is not properly handled during construction of the “failed log-in attempts over telnet” log view.

Affected configurations

NVD
Node
huaweiecho_life_hg8247_firmwareMatchv1r006c00s120
AND
huaweiecho_lifeMatchhg8247

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.1%

Related for CVE-2014-0337